mitre-attack / car

Cyber Analytics Repository
Apache License 2.0
889 stars 300 forks source link

Car-2021-12-001.yaml-T1053.005 #137

Closed Ptylu closed 2 years ago

Ptylu commented 2 years ago

-Finished- Detection of creation or modification of Scheduled Task with suspicious script, extension or user writable path. Attacker may create or modify Scheduled Task for execution of malicious code with a persistance. Detection focus at the same tine on the EventID 4688 with the process creation (SCHTASKS) and EventID 4698 for the Scheduled Task creation/modification event log.